← Vulnerability feed

Vulnerability record · CVE-2024-0204 · published 22 January 2024

CVE-2024-0204: Fortra GoAnywhere MFT authentication bypass in admin portal

Fortra · Goanywhere Managed File Transfer

GoAnywhere MFT before 7.4.1 contains an authentication bypass (CWE-425, forced browsing) in the administration portal that lets an unauthenticated user create an administrative account. Because the resulting account is a full admin, the flaw effectively hands over control of the managed file transfer server, a high-value system that often holds credentials and moves sensitive data.

9.8 CVSS 3.1 Critical EPSS 95% · top 0.1% CWE-425 · CWE-425
9.8CVSS 3.1 base score
95%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to create an admin user via the administration portal.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable bypass that yields full admin control of a sensitive file transfer server, with a CVSS of 9.8 and near-maximum EPSS.

What it is

GoAnywhere MFT before 7.4.1 contains an authentication bypass (CWE-425, forced browsing) in the administration portal that lets an unauthenticated user create an administrative account. Because the resulting account is a full admin, the flaw effectively hands over control of the managed file transfer server, a high-value system that often holds credentials and moves sensitive data.

Impact

An unauthenticated attacker gains a working administrative account on the GoAnywhere MFT instance, giving full control over its configuration, file transfer jobs and stored credentials. From there the attacker can read or move transferred data and potentially pivot into connected systems.

Attack surface

Reachable over the network through the administration portal; the CVSS vector is AV:N/AC:L/PR:N/UI:N, so no authentication and no user interaction are required. The description does not specify whether the portal must be internet-facing or which exact endpoint is abused.

Exploitation

Not listed in CISA KEV and no ransomware group is documented in this record, but EPSS is very high (0.95086, 99.859th percentile), indicating strong likelihood of exploitation. Reference tags include a third-party advisory and a Packet Storm entry for unauthenticated remote code execution, suggesting public technical detail exists, though the record does not confirm active exploitation.

What to do

  • Upgrade GoAnywhere MFT to 7.4.1 or later; this is the only complete fix.
  • If immediate patching is not possible, restrict access to the administration portal to trusted management networks and block it from the internet.
  • Audit existing admin accounts for unauthorized or unexpected additions and remove any that cannot be accounted for.
  • Rotate credentials and keys stored or managed by the GoAnywhere instance if compromise is suspected.
  • Monitor vendor advisory FI-2024-001 for updated guidance.

Detection

  • Review GoAnywhere MFT logs for admin account creation events, especially from unexpected source IPs or outside change windows.
  • Alert on access to administration portal endpoints from unauthenticated or external sources.
  • Baseline the set of administrative accounts and alert on any new admin user.
  • Correlate portal access with subsequent configuration changes, job creation or outbound connections.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-0204 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-10035Fortra GoAnywhere MFT License Servlet deserialization to command injectionThe License Servlet in Fortra GoAnywhere MFT deserializes untrusted data, and an attacker who can present a validly forged license response signature…KEVEPSS 100%analysed7.2CVE-2023-0669Fortra GoAnywhere MFT pre-auth deserialization command injectionFortra GoAnywhere MFT deserializes an attacker-controlled object in the License Response Servlet, allowing command injection before authentication. T…KEVEPSS 100%analysed7.3CVE-2025-14362Fortra goanywhere managed file transfer improper restriction of authentication attempts vulnerabilityThe login limit is not enforced on the SFTP service of Fortra's GoAnywhere MFT prior to 7.10.0 if the Web User attempting to be logged in to is confi…EPSS 0.19%6.5CVE-2026-1089Fortra goanywhere managed file transfer injection vulnerabilityUser‑Controlled HTTP Header in Fortra's GoAnywhere MFT prior to version 7.10.0 allows attackers to trigger a DNS lookup, as well as DNS Rebinding and…EPSS 0.23%6.5CVE-2024-25157Fortra goanywhere managed file transfer improper authentication vulnerabilityAn authentication bypass vulnerability in GoAnywhere MFT prior to 7.6.0 allows Admin Users with access to the Agent Console to circumvent some permis…EPSS 0.50%6.5CVE-2024-25156Fortra goanywhere managed file transfer path traversal vulnerabilityA path traversal vulnerability exists in GoAnywhere MFT prior to 7.4.2 which allows attackers to circumvent endpoint-specific permission checks in th…EPSS 0.39%5.4CVE-2026-0972Fortra goanywhere managed file transfer injection vulnerabilityHTML injection is possible in system generated emails in Fortra's GoAnywhere MFT prior to 7.10.0. Note: The title, details, and description of this C…EPSS 0.16%5.4CVE-2024-11922Fortra goanywhere managed file transfer cross-site scripting vulnerabilityMissing input validation in certain features of the Web Client of Fortra's GoAnywhere prior to version 7.8.0 allows an attacker with permission to tr…EPSS 0.23%

Source: NIST National Vulnerability Database (record CVE-2024-0204), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.